Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Generic 16.WTC + další???

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Jenča
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 09 led 2010 21:43

Generic 16.WTC + další???

#1 Příspěvek od Jenča »

Dobrý den,
vlastní vinou jsem si pomohl k virům.
Příznaky: poskytovatel Internetu zakázal SMTP (nyní již povolil), vyskakovala okna v MS IE (který takřka nepoužívám), AVG ohlašuje Generic 16.WTC - nyní již jen v _restore.
Chování PC v pořádku (alespoň na první pohled).
Děkuji


Logfile of random's system information tool 1.06 (written by random/random)
Run by MJ at 2010-01-09 21:40:32
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 192 GB (87%) free of 220 GB
Total RAM: 3036 MB (82% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:40:42, on 9.1.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTBoardService.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Documents and Settings\MJ\Plocha\RSIT.exe
C:\Program Files\trend micro\MJ.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SMART Notebook Download Plugin - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - C:\Program Files\SMART Technologies\SMART Notebook\NotebookPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout pomocí NetXferu - C:\Program Files\Xi\NetXfer\NXAddLink.html
O8 - Extra context menu item: Stáhnout vše pomocí Net&Xferu - C:\Program Files\Xi\NetXfer\NXAddList.html
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 5523213239
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 5523297692
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: Služba SMART Board (SMART Board Service) - SMART Technologies - C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTBoardService.exe
O23 - Service: SMART SNMP Agent Service - SMART Technologies ULC - C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTSNMPAgent.exe
O23 - Service: Webový server SMART (SMART Web Server) - Unknown owner - C:\Program Files\SMART Technologies\SMART Board Drivers\WebServer.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe

--
End of file - 8274 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-12-10 1111320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67BCF957-85FC-4036-8DC4-D4D80E00A77B}]
CIEDownload Object - C:\Program Files\SMART Technologies\SMART Notebook\NotebookPlugin.dll [2009-08-05 529704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-02-03 61440]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-02-06 1430824]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-12-10 2043160]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2004-11-02 32768]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2008-07-25 888832]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2009-07-27 288312]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-01-08 3055616]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-01-08 3055616]
"IntelliPoint"=C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2009-06-01 1468296]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2010-01-08 3055616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-02-03 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-10-13 11952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\AVG\AVG8\avgam.exe"="C:\Program Files\AVG\AVG8\avgam.exe:*:Enabled:avgam.exe"
"C:\Program Files\AVG\AVG8\avgdiag.exe"="C:\Program Files\AVG\AVG8\avgdiag.exe:*:Enabled:avgdiag.exe"
"C:\Program Files\AVG\AVG8\avgdiagex.exe"="C:\Program Files\AVG\AVG8\avgdiagex.exe:*:Enabled:avgdiagex.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\SMART Technologies\SMART Board Drivers\UCGui.exe"="C:\Program Files\SMART Technologies\SMART Board Drivers\UCGui.exe:*:Enabled:SMART Universal Controller Interface"
"C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTSNMPAgent.exe"="C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTSNMPAgent.exe:*:Enabled:SMART SNMPAgent"
"C:\Program Files\SMART Technologies\SMART Board Drivers\UCService.exe"="C:\Program Files\SMART Technologies\SMART Board Drivers\UCService.exe:*:Enabled:SMART Universal Controller Service"
"C:\Program Files\SMART Technologies\SMART Board Drivers\WebServer.exe"="C:\Program Files\SMART Technologies\SMART Board Drivers\WebServer.exe:*:Enabled:SMART Web Server"
"C:\Program Files\GameTop.com\Extreme Racers\Extreme Racers.exe"="C:\Program Files\GameTop.com\Extreme Racers\Extreme Racers.exe:*:Enabled:Cipher Game Engine"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Xi\NetXfer\NetTransport.exe"="C:\Program Files\Xi\NetXfer\NetTransport.exe:*:Enabled:NetXfer Download Manager"
"C:\WINDOWS\system32\lpfmp.exe"="C:\WINDOWS\system32\lpfmp.exe:*:Enabled:ENABLE"
"C:\Documents and Settings\MJ\nrl.exe"="C:\Documents and Settings\MJ\nrl.exe:*:Enabled:ENABLE"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
shell\AutoRun\command - H:\SamsungSoftware\APPInst.exe


======List of files/folders created in the last 1 months======

2010-01-09 13:05:06 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2010-01-08 23:00:05 ----D---- C:\WINDOWS\Minidump
2010-01-08 21:55:39 ----D---- C:\rsit
2010-01-08 21:55:39 ----D---- C:\Program Files\trend micro
2010-01-08 21:51:15 ----D---- C:\Documents and Settings\All Users\Data aplikací\PrevxCSI
2010-01-08 21:51:09 ----A---- C:\WINDOWS\wininit.ini
2010-01-06 18:46:02 ----D---- C:\Config.Msi
2010-01-06 17:52:03 ----A---- C:\WINDOWS\ntbtlog.txt
2010-01-05 22:24:41 ----D---- C:\Program Files\ESET
2010-01-04 22:52:19 ----HD---- C:\$AVG8.VAULT$
2010-01-02 14:49:33 ----D---- C:\Program Files\Xi
2009-12-24 11:15:47 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$

======List of files/folders modified in the last 1 months======

2010-01-09 21:40:05 ----D---- C:\WINDOWS\Prefetch
2010-01-09 21:39:28 ----D---- C:\WINDOWS\Temp
2010-01-09 21:37:48 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-09 21:15:24 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-09 21:14:25 ----D---- C:\Program Files\Mozilla Firefox
2010-01-09 21:01:42 ----D---- C:\WINDOWS\system32\config
2010-01-09 20:03:06 ----SHD---- C:\WINDOWS\Installer
2010-01-09 13:11:33 ----RD---- C:\Program Files
2010-01-09 13:10:00 ----D---- C:\Program Files\Internet Explorer
2010-01-09 13:03:51 ----D---- C:\WINDOWS\system32\drivers
2010-01-09 00:20:10 ----D---- C:\WINDOWS\system32
2010-01-08 23:57:58 ----D---- C:\Program Files\Microsoft IntelliPoint
2010-01-08 23:00:05 ----D---- C:\WINDOWS
2010-01-08 21:50:58 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-01-06 19:09:25 ----HD---- C:\WINDOWS\inf
2010-01-06 18:45:15 ----D---- C:\WINDOWS\system32\Restore
2010-01-06 18:44:33 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-01-06 17:58:43 ----SHD---- C:\RECYCLER
2010-01-06 17:57:15 ----D---- C:\Documents and Settings
2010-01-05 23:32:48 ----D---- C:\stah
2010-01-05 22:24:43 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-01-05 19:46:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\avg8
2010-01-04 23:11:28 ----SD---- C:\WINDOWS\Tasks
2010-01-04 22:52:26 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-12-27 14:05:04 ----D---- C:\Documents and Settings\MJ\Data aplikací\XnView
2009-12-24 20:28:33 ----D---- C:\WINDOWS\AppPatch
2009-12-24 11:15:46 ----HD---- C:\WINDOWS\$hf_mig$
2009-12-24 11:15:44 ----A---- C:\WINDOWS\imsins.BAK
2009-12-19 09:13:45 ----D---- C:\Program Files\CDBurnerXP
2009-12-14 20:20:24 ----D---- C:\Documents and Settings\MJ\Data aplikací\Zoner

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-10-13 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-10-13 27784]
R1 AvgTdiX;AVG8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-10-13 108552]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SbFw;SbFw; C:\WINDOWS\system32\drivers\SbFw.sys [2008-10-31 270888]
R1 sbhips;Sunbelt HIPS Driver; C:\WINDOWS\system32\drivers\sbhips.sys [2008-06-21 66600]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R3 Accelerometer;Accelerometer; C:\WINDOWS\system32\DRIVERS\Accelerometer.sys [2006-10-17 22016]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2009-07-20 339456]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2009-03-12 112896]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-02-04 3488768]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2009-10-13 1735296]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\WINDOWS\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys [2009-06-01 27792]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport; C:\WINDOWS\system32\DRIVERS\sbfwim.sys [2008-06-21 65576]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2009-02-06 205232]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2009-06-04 297728]
S2 BrPar;BrPar; C:\WINDOWS\System32\drivers\BrPar.sys [2000-07-24 19537]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2008-11-21 1204128]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2009-09-28 7168]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2008-08-26 14336]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-02-03 602112]
R2 avg8emc;AVG8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-10-13 908056]
R2 avg8wd;AVG8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-10-13 297752]
R2 Brother XP spl Service;BrSplService; C:\WINDOWS\system32\brsvc01a.exe [2002-04-11 57344]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2009-07-13 71096]
R2 SbPF.Launcher;SbPF.Launcher; C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [2008-10-31 95528]
R2 SMART Board Service;Služba SMART Board; C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTBoardService.exe [2009-07-23 2596864]
R2 SPF4;Sunbelt Personal Firewall 4; C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [2008-10-31 1365288]
R2 yksvc;Marvell Yukon Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2009-04-30 229944]
S2 SSHNAS;SSHNAS; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SMART SNMP Agent Service;SMART SNMP Agent Service; C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTSNMPAgent.exe [2009-07-23 1048576]
S3 SMART Web Server;Webový server SMART; C:\Program Files\SMART Technologies\SMART Board Drivers\WebServer.exe [2009-07-23 1245184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Generic 16.WTC + další???

#2 Příspěvek od Rudy »

Pro jistotu ještě udělejte sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Jenča
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 09 led 2010 21:43

Re: Generic 16.WTC + další???

#3 Příspěvek od Jenča »

Malwarebytes' Anti-Malware 1.44
Verze databáze: 3531
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

9.1.2010 23:38:54
mbam-log-2010-01-09 (23-38-46).txt

Typ kontroly: Kompletní kontrola (C:\|D:\|)
Zkontrolované objekty: 248718
Uplynulý čas: 1 hour(s), 1 minute(s), 29 second(s)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 5
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované adresáře: 0
Infikované soubory: 154

Infikované procesy v paměti:
(Nebyly nalezeny žádné škodlivé položky)

Infikované moduly v paměti:
(Nebyly nalezeny žádné škodlivé položky)

Infikované klíče registru:
HKEY_CURRENT_USER\SOFTWARE\LREC75DND7 (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\E8WECRKKMV (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS (Trojan.Renos) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> No action taken.

Infikované hodnoty registru:
(Nebyly nalezeny žádné škodlivé položky)

Infikované datové položky registru:
(Nebyly nalezeny žádné škodlivé položky)

Infikované adresáře:
(Nebyly nalezeny žádné škodlivé položky)

Infikované soubory:
C:\Program Files\Spybot - Search & Destroy\teatimer.exe.delme68 (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014203.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014204.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014205.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014206.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014207.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014208.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014209.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014210.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014211.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014222.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014239.dll (Trojan.Downloader) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014255.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014256.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014257.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014258.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014259.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014260.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014261.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014262.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014263.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014264.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014265.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014266.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014267.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014290.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014291.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014292.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014293.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014294.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014295.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014296.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014297.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014298.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014299.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014300.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014301.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014302.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014303.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014269.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014325.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014326.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014327.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014328.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014329.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014330.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014331.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014332.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014333.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014334.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014335.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014336.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014337.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP123\A0014340.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP124\A0014372.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP124\A0014373.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP124\A0014374.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP124\A0014375.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP124\A0014376.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP124\A0014377.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP124\A0014378.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP124\A0014379.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP124\A0014380.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP124\A0014381.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP124\A0014383.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP124\A0014384.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP124\A0014409.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP124\A0014455.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP124\A0014382.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014497.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014498.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014499.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014500.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014501.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014502.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014503.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014504.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014505.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014506.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014508.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014509.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014534.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014577.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014507.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014614.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014615.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014616.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014617.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014618.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014619.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014620.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014621.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014622.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014623.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014624.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014625.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014626.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP125\A0014627.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014652.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014670.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014688.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014640.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014641.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014642.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014643.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014644.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014645.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014646.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014647.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014648.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014649.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014650.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014651.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014660.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014661.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014662.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014663.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014664.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014665.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014666.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014667.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014668.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014669.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014671.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014672.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014678.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014684.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014685.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014686.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014687.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014689.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014690.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014691.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014692.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014693.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014694.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014696.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP126\A0014697.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP128\A0014711.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP129\A0014750.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP129\A0014762.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP129\A0014763.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP129\A0014764.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP129\A0014765.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP129\A0014766.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP129\A0014767.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP129\A0014768.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP129\A0014769.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP129\A0014771.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP129\A0014773.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP129\A0014775.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP129\A0014803.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{5C6A0536-85B1-4A41-9D85-3330A867359A}\RP129\A0014770.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\MJ\Local Settings\Temp\wmpscfgs.exe (Trojan.Agent) -> No action taken.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Generic 16.WTC + další???

#4 Příspěvek od Rudy »

Vše smažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Jenča
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 09 led 2010 21:43

Re: Generic 16.WTC + další???

#5 Příspěvek od Jenča »

Smazáno...

Opětovný sken MBAM nic nenalezl.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Generic 16.WTC + další???

#6 Příspěvek od Rudy »

PC by mělo být čisté.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Jenča
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 09 led 2010 21:43

Re: Generic 16.WTC + další???

#7 Příspěvek od Jenča »

Děkuji za pomoc a Váš čas.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Generic 16.WTC + další???

#8 Příspěvek od Rudy »

Nemáte zač!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět